new-project

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the bash tool to execute internal scripts and public framework scaffolders.
  • Evidence includes the invocation of bun new-project/scripts/new-project.ts and bun scripts/extract-skill.ts to manage the project environment and automate pattern extraction.
  • [EXTERNAL_DOWNLOADS]: The scaffolding process retrieves templates and official packages from external sources via standard package managers and version control.
  • The engine utilizes git clone for repositories like https://github.com/ariabuilder/aria.git and npx or bun create for various framework and CMS starters (e.g., Next.js, Medusa, Payload CMS).
  • [INDIRECT_PROMPT_INJECTION]: The skill's 'Client Intake' stage creates a surface where user-provided text data influences the agent's behavior during documentation generation.
  • Ingestion points: Interactive user responses are stored in Client-Intake/00-Intake-Brief.md and .agents/context/product.md.
  • Boundary markers: The skill documentation lacks explicit delimiters or 'ignore' instructions for processing user-supplied data in the brief.
  • Capability inventory: The agent uses bash and write_to_file to transform these inputs into further project documents.
  • Sanitization: There are no defined filters or sanitization steps for content ingested from the intake brief before it is processed by the agent.
  • [DATA_EXFILTRATION]: The engine handles sensitive infrastructure information through its 'Technical Intake' process.
  • Documentation specifies the collection of credentials, repository access tokens, and hosting details in 04-Technical-Intake/ and .env files.
  • This risk is mitigated by the 'Vibeguard' protocol mentioned in SKILL.md, which uses a pre-commit hook (scripts/pre-commit.sh) to detect and block secrets from being committed to version control.
  • [DYNAMIC_EXECUTION]: The skill includes functionality for 'Skill Extraction' which involves generating new executable skill files at runtime.
  • The scripts/extract-skill.ts script allows the agent to generate new SKILL.md contracts and platform definitions based on recurring logic patterns discovered during development.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:23 PM
Security Audit — agent-trust-hub — new-project